2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-58121MEDIUM5.4Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4....
CVE-2025-8084MEDIUM6.8The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3....
CVE-2025-63892MEDIUM6.8A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_c...
CVE-2025-63883MEDIUM5.4A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client...
CVE-2025-59117MEDIUM4.8Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu...
CVE-2025-59116MEDIUM5.3Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow ...
CVE-2025-59115MEDIUM5.4Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation...
CVE-2025-59114MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft spec...
CVE-2025-59112MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft specia...
CVE-2025-59111MEDIUM6.5Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET reques...
CVE-2025-59110MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechani...
CVE-2025-55179MEDIUM5.4Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.2...
CVE-2025-13349MEDIUM5.4A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown p...
CVE-2025-12545MEDIUM5.3The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is...
CVE-2025-12376MEDIUM6.4The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request ...
CVE-2025-10158MEDIUM4.3A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based bu...
CVE-2025-41350MEDIUM5.4Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store...
CVE-2025-41349MEDIUM5.4Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store...
CVE-2025-13343MEDIUM5.4A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function o...
CVE-2025-11427MEDIUM5.8The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forg...
CVE-2025-13196MEDIUM5.4The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Open Str...
CVE-2025-13133MEDIUM6.6The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, ...
CVE-2025-12691MEDIUM6.4The Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2025-12639MEDIUM4.3The wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions plugin for WordPress is vulnerable to authorizati...
CVE-2025-12481MEDIUM4.3The WP Duplicate Page plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now